CVE-2026-79304
- EPSS 0.54%
- Veröffentlicht 23.09.2026 00:00:00
- Zuletzt bearbeitet 24.09.2026 21:18:44
CyberPanel 1.9.1 contains a path traversal vulnerability in the readFileContents method of the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply an arbitrary absolute or out-of-scope...
CVE-2026-79306
- EPSS 0.33%
- Veröffentlicht 23.09.2026 00:00:00
- Zuletzt bearbeitet 25.09.2026 15:17:55
CyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply absolute or otherwise out-of-sc...
CVE-2026-29810
- EPSS 0.3%
- Veröffentlicht 13.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 13:42:47
CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.
CVE-2026-29811
- EPSS 0.25%
- Veröffentlicht 13.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 13:42:45
CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.
CVE-2026-29812
- EPSS 0.22%
- Veröffentlicht 13.09.2026 00:00:00
- Zuletzt bearbeitet 16.09.2026 13:42:47
CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.
CVE-2021-47949
- EPSS 0.53%
- Veröffentlicht 10.05.2026 13:16:31
- Zuletzt bearbeitet 06.10.2026 22:10:00
CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager controller endpoint. Attackers can manipulate the comp...
CVE-2026-41473
- EPSS 0.77%
- Veröffentlicht 24.04.2026 20:40:36
- Zuletzt bearbeitet 11.08.2026 18:17:26
CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/s...
CVE-2026-41472
- EPSS 0.5%
- Veröffentlicht 24.04.2026 20:40:12
- Zuletzt bearbeitet 11.08.2026 18:17:25
CyberPanel versions prior to 2.4.5 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScri...
CVE-2024-56112
- EPSS 0.25%
- Veröffentlicht 16.12.2024 06:15:07
- Zuletzt bearbeitet 05.09.2025 00:30:15
CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.
CVE-2024-53376
- EPSS 10.97%
- Veröffentlicht 16.12.2024 04:15:05
- Zuletzt bearbeitet 05.09.2025 00:33:27
CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.